Перейти к содержанию

I can't decrypt images infected by CryptXXX with RannohDecryptor


Рекомендуемые сообщения

Good afternoon:

I have some files encrypted by CryptXXX 1.0 (I checked it on ID-Ransomware website) and when I use RannohDecryptor it can decrypt most of files except images. Here you have a log:

 

7:23:50.0466 0x5024  Trojan-Ransom.Win32.Rannoh decryptor tool 1.9.6.1 Jan 25 2017 20:07:00
17:23:52.0473 0x5024  ============================================================
17:23:52.0473 0x5024  Current date / time: 2017/08/30 17:23:52.0473
17:23:52.0473 0x5024  SystemInfo:
17:23:52.0474 0x5024  
17:23:52.0474 0x5024  OS Version: 6.2.9200 ServicePack: 0.0
17:23:52.0474 0x5024  Product type: Workstation
17:23:52.0474 0x5024  ComputerName: LAPTOP-9TUCH60U
17:23:52.0474 0x5024  UserName: win10
17:23:52.0474 0x5024  Windows directory: C:\WINDOWS
17:23:52.0474 0x5024  System windows directory: C:\WINDOWS
17:23:52.0474 0x5024  Running under WOW64
17:23:52.0474 0x5024  Processor architecture: Intel x64
17:23:52.0474 0x5024  Number of processors: 4
17:23:52.0474 0x5024  Page size: 0x1000
17:23:52.0474 0x5024  Boot type: Normal boot
17:23:52.0474 0x5024  ============================================================
17:23:52.0648 0x5024  Initialize success
17:24:59.0357 0x4bd8  ProcessDriveEnumEx: Drive C:\ type 3:0
17:24:59.0463 0x4bd8  Processing file: \\?\C:\0\German\00 022.jpg.crypt
17:24:59.0463 0x4bd8  Cannot decrypt file: \\?\C:\0\German\00 022.jpg.crypt, size too large.
17:24:59.0463 0x4bd8  Cannot decrypt: \\?\C:\0\German\00 022.jpg.crypt
17:24:59.0465 0x4bd8  Processing file: \\?\C:\0\German\EXCEL PROPUESTA AVANTE.xls.crypt
17:24:59.0468 0x4bd8  Decrypted successfully: \\?\C:\0\German\EXCEL PROPUESTA AVANTE.xls.crypt
17:25:07.0296 0x4bd8  ProcessDriveEnumEx: Drive D:\ type 3:0
17:25:07.0296 0x4bd8  
17:25:07.0296 0x4bd8  Statistic:
17:25:07.0296 0x4bd8  Processed: 1089
17:25:07.0296 0x4bd8  Suspicious: 0
17:25:07.0296 0x4bd8  Found: 2
17:25:07.0296 0x4bd8  Decrypted: 1
17:25:07.0296 0x4bd8  ================================================================================
17:25:07.0296 0x4bd8  Scan finished
17:25:07.0296 0x4bd8  ================================================================================
17:32:03.0187 0x0ba8  Deinitialize success
 
 
 
Size too large??? The image is only 180 KB...(?)
Please, can anybody help me?
Thank you.
Ссылка на комментарий
Поделиться на другие сайты

Пожалуйста, войдите, чтобы комментировать

Вы сможете оставить комментарий после входа в



Войти
×
×
  • Создать...